Live data from Hacker News

IAmA a malware coder and botnet operator, AMA

reddit.com

31–40 of 203 posts

Re: IAmA a malware coder and botnet operator, AMA

#32

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

As someone in the financial payment industry, let me shed some light on it. 3DSecure (the generic name) when used, generally prevents the user from issuing chargebacks, even in the case of fraud. It's a Terms & Conditions change basically for that purchase. Since your credentials can be hijacked at your web browser level, it is possible to give up your credentials AND give up your ability to re-mediate the issue later.

If you are purchasing stuff online, I advise using a credit card and CVV. Federal law (in the US) limits your damages to $50 total in the event of Fraud. (Not true of debit cards, or 3DSecure).

http://en.wikipedia.org/wiki/3-D_Secure

Re: IAmA a malware coder and botnet operator, AMA

#33
post #7

The CVV2 is not recorded in the mag stripe.

Ooohh.. so that's why those websites ask for it. Learn something new every day :S

Also, whether websites do or don't ask for it depends on their (and their merchant banking) risk appetite.

Sometimes banks make it mandatory, sometimes not. It's not * required* to make a transaction, it merely offers an (optional) extra level of security.

Re: IAmA a malware coder and botnet operator, AMA

#34
post #18
post #14

Earlier quoted context omitted.

From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.

For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.

He is using Tor, which gets a lot of criticism for not being secure but actually defeats Syrian or Chinese governments. If the US can track a hidden service in Tor, they will probably not waste this trump by catching such a small fish.

Re: IAmA a malware coder and botnet operator, AMA

#35

Most of what he says is obvious stuff and the emphasis he puts on how much he modifies stuff makes me assume he's someone that just runs programs and doesn't have any unique insight, but he does make one interesting point: > Try to use "Verified-By-Visa" and "Mastercard-Securecode" as rarely as possible. If only your CVV2 code is getting sniffed, you are not liable for any damage, because the code is physicly printed…

I really wouldn't be surprised. The security group at my university do a lot of stuff on banking security, and from what I've heard, this was one of the main reasons behind the switch to chip-and-PIN in the UK --- the user is now liable when his card gets stolen and used.

See, for example, Tetris on a ('secure hardware' platform) chip & pin machine[1]

The same group (security research at cambridge) are also the ones who produced the 'chip and pin is a joke'[2] paper you might be referring to.

[1] http://www.lightbluetouchpaper.org/2006/12/24/chip-pin-termi...

[2] http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...

Re: IAmA a malware coder and botnet operator, AMA

#36
post #18
post #14

Earlier quoted context omitted.

From what he says I agree that he seems either stupid or a liar, but I'm not sure about your premise, it's not hard to post an AMA that can't be linked to you.

For the average cyber-stalker, that's true. But I'd wager if some government agency actually wanted to track him down (he's probably too low-value of a target), he's revealed more than enough bits of information about his personal life for them to do so.

[deleted]

Re: IAmA a malware coder and botnet operator, AMA

#37
Each time I see such showing off I get more convinced that such reports are mostly fake and done by script kiddies.

Personally I wouldn't go through the hassle of doing this. I mean, is this really more profitable than a a job as a developer, sysadmin, tester, etc? I wouldn't think so.

But could anybody explain me this simple thing: How does he prevent being traced? Hiding behind Tor will basically do nothing, he will get traced in no time.

So this still confuses me rather much.... so he sends out all sorts of tricks to capture zombies, how does he avoids hitting the wrong targets? (police, feds, etc)

Re: IAmA a malware coder and botnet operator, AMA

#38
post #13

Earlier quoted context omitted.

Ooohh.. so that's why those websites ask for it. Learn something new every day :S

They can't store the CVV2 either. Doing so, even encrypted, violates PCI-DSS.

So, if you don't care about violating the terms of PCI-DSS, you can store the CVV2/CVC/whatever. I bet lots of places do. In fact, I worked for a Visa Level-1 merchant that had a card processing system that used an Oracle DB table as a queue for outgoing authorization requests. The table held the CVV2/CVC/whatever for as long as it took to get an authorization or a timeout, whichever came first. We passed the PCI audit, even though the auditors knew about it.

Given that there's only 1,000 CVV2 values (10,000 for Amex) isn't putting so much into CVV2 value a bit ridiculous? Someone who really wanted to could get a CVV2 value in only 500 auth attempts on average.

Re: IAmA a malware coder and botnet operator, AMA

#39
There's so many legal ways this guy could make just as much money with his skills. I never understood why someone is willing to put his freedom at risk when that is the case.

I guess he's just lazy or thinks he's incapable of making as much as easily legally, maybe he likes the thrill and challenge of it all, maybe he thinks he's invincible and there's zero chance of him getting caught. Either way he's very foolish for continuing to do this especially if he has no endgame in sight.

Post reply on HN